Access Request
An Access Request is a formal request for new, changed, or extended access to a system, entitlement, or role.
Explore the concepts used across Identity and Access Management, Identity Governance, Access Management, privileged access, authorization and identity security.
Definitions are organized to support search and navigation between related concepts.
An Access Request is a formal request for new, changed, or extended access to a system, entitlement, or role.
Account Correlation is the process of linking discovered accounts in target systems to the correct digital identity in the IAM system.
Account Provisioning is the creation and maintenance of system-specific accounts linked to an identity.
The Alternative Scenario is the second-best onboarding path combining modern authentication with managed account lifecycle in the target application.
An API-Based Integration Path is a custom onboarding route that manages the application through its exposed APIs.
Application Onboarding is the structured process of connecting a new application to the IAM control model for authentication, identity lifecycle, and access governance.
An Approval Workflow is the sequence of review and decision steps required before access is provisioned or changed.
Attribute Mapping is the process of translating identity data from a source model into the attribute structure required by a target system.
Automated Provisioning is the execution of provisioning tasks through system-driven workflows rather than manual intervention.
Birthright Access is the default access automatically granted to an identity based on basic organizational attributes or status.
Centralized Repository Dependency is the degree to which an application is already linked to the enterprise identity repository used for onboarding acceleration.
The CIAM Integration Layer is the set of connectors and exchanges used to connect customer identity data with surrounding business and marketing systems.
Custom Connector Normalization is the habit of accepting target-specific integration code as a normal end state instead of a constrained exception.
A Custom Development Connector is an application-specific integration built when standard protocols are not sufficient.
Delta Provisioning is a provisioning approach that processes only the changes that occurred since the last synchronization cycle.
Deprovisioning is the process of removing, disabling, or revoking accounts and access rights when they are no longer justified.
Directory Synchronization is the ongoing synchronization of identity objects and attributes between directories or between a directory and other systems.
A Dormant Account is an account that still exists but shows no activity for a prolonged period and may no longer be needed.
An Email-Driven Access Process is an access workflow handled mainly through informal email exchanges instead of structured request channels.
Emergency Deprovisioning is the urgent removal of access outside normal timelines due to security, legal, or operational risk.
Entitlement Provisioning is the assignment and withdrawal of specific access rights, privileges, or functional grants in target systems.
Event-Driven Provisioning is a provisioning model where lifecycle actions are triggered by discrete events published by one or more upstream systems.
The Favorite Scenario is the preferred onboarding path in which the application supports modern delegated authentication and minimizes local account persistence.
Forced Local Account Persistence is the design choice of keeping permanent local user accounts in an application even when a lighter federated model would be possible.